Different error message on wrong user name and password makes it possible to check account existance. Directory traversal allows to access files outside web root.
vulners.com/securityvulns/securityvulns:doc:2418
vulners.com/securityvulns/securityvulns:doc:2650
vulners.com/securityvulns/securityvulns:doc:2948
vulners.com/securityvulns/securityvulns:doc:2959